CISSP Blog Post 7, Domain 3: Access Control Models


Credit: Post based on CISSP course presented by Dennis Lee, November 2018

There are many models for designing Access Controls. Famous models include:

The Graham-Denning Model – this model accounts for Confidentiality, Integrity, and Availability (CIA). It includes a mechanism called a Monitor that enforces access from subjects to objects.

Graham-Denning Access Control Model
Graham-Denning Access Control Model

The James Anderson Model is similar to the Graham-Denning Model, however this model has a “Reference Monitor” that is an enhanced ruleset version of the Graham-Denning “Monitor” mechanism.

James Anderson Access Control Model
James Anderson Access Control Model

The Harrison, Ruzzon, Ullman (HRU) Model formalized the access control matrix as a model.

Harrison, Ruzzon, Ullman (HRU) Access Control Model
Harrison, Ruzzon, Ullman (HRU) Access Control Model